Generate a Certificate Signing Request (CSR) File for Cisco ASA


To generate a certificate signing request (CSR) for Cisco ASA 5510, perform the following steps:
Step 1:  Generate a key pair
1.    Within ASDM, click Configuration > Device Management
2.    Click Certificate Management > Identity Certificates > Add > Add a new identity certificate
3.    For the Key Pair, click New > Enter new key pair name
4.    Enter a unique key pair name for the certificate
5.    Select the key size as 2048
6.    To complete the generation of the key pair, click Generate Now

Step 2: Generate a certificate signing request (CSR) file
1.    To enter certificate information, click Select
2.    From the drop-down list, select the following attributes > enter value > click Add
Note: The following fields are required: C (Country), St (State), L (Locality), O (Organization Name), OU (Organizational Unit), CN (Common Name)
3.    Once the appropriate values are added, click OK > Advanced
4.    In the FQDN field, enter the FQDN that will be used to access the device from the Internet: NOTE - If enrolling for a Subject Alternative Name certificate leave this field blank.
Note: This value should be same FQDN you used for the Common Name (CN)
5.    Click OK >  Add Certificate > Browse
6.    Choose a location where to save the request file


Most Imp .Java Keytool Commands



      Generate a Java keystore and key pair:

            keytool -genkey -alias mydomain -keyalg RSA -keystore keystore.jks -keysize 2048
    Generate a certificate signing request (CSR) for an existing Java keystore: 
            keytool -certreq -alias mydomain -keystore keystore.jks -file mydomain.csr
    Generate a keystore and self-signed certificate:
           keytool -genkey -keyalg RSA -alias selfsigned -keystore keystore.jks -storepass password -validity 360 -keysize 2048
     
Certificate import commands in keystore:
Import a root CA certificate to an existing Java keystore:
               keytool -import -trustcacerts -alias root -file root.crt -keystore keystore.jks
           Import a intermediate CA certificate to an existing Java keystore:
              keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore keystore.jks
Import a signed SSL primary certificate to an existing Java keystore:
                keytool -import -trustcacerts -alias mydomain -file mydomain.crt -keystore keystore.jks

    Java Keytool Commands for Conversion:

             If you need to change the type of keystore.
PFX keystore to JKS keystore:
keytool -importkeystore -srckeystore mypfxfile.pfx -srcstoretype pkcs12 -destkeystore newjkskeystore.jks -deststoretype JKS
JKS keystore to PFX keystore:
keytool -importkeystore -srckeystore myjksfile.jks -srcstoretype JKS -deststoretype PKCS12 -destkeystore newpfxkeystore.pfx
    Other Java Keytool Commands:
Delete a certificate from a Java Keytool keystore:
keytool -delete -alias mydomain -keystore keystore.jks
Change a Java keystore password:
keytool -storepasswd -new newstorepass -keystore keystore.jks
Export a certificate from a keystore:
keytool -export -alias mydomain -file mydomain.crt -keystore keystore.jks
List Trusted CA Certs:
keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts
Import New CA into Trusted Certs:
keytool -import -trustcacerts -file /path/to/ca/ca.pem -alias mydomain -keystore $JAVA_HOME/jre/lib/security/cacerts

Most OpenSSL Commands




      Convert PEM to DER:
       openssl x509 -outform der -in certificate.pem -out certificate.der

       Convert DER to PEM:
       openssl x509 -inform der -in certificate.der -out certificate.pem

       Convert PEM/CRT to P7B:
       openssl crl2pkcs7 -nocrl -certfile certificate.crt -out certificate.p7b -certfile CACert.crt

       Convert P7B to PEM/CRT:
       openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt


        Convert PEM/CRT & Private Key to PFX/P12:
       openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt

        Convert P7B to PFX:
        openssl pkcs12 -export -in certificate.cer -inkey privateKey.key -out certificate.pfx -certfile CACert.cer

        Convert PFX to PEM/CRT and Private Key
                 openssl pkcs12 -in certificate.pfx -out certificate.crt -nodes

   


         OpenSSL command to remove private key password
                                              Or
          To convert simple private to   RSA   private.key

        openssl rsa -in file.key -out newfile.key
   
    openssl command print out md5 checksums of the certificate and key
        openssl x509 -noout -modulus -in server.crt| openssl md5
                openssl rsa -noout -modulus -in server.key| openssl md5
   




Installing SSL Certificate on Zimbra


Using the CLI
·         1. Get the certificate from ssl authority in crt/txt format, or sometimes like a zip file.
·         2. Place the Certificate on your Zimbra mailbox server. You should receive below files:
o    Root.crt
o    Intermediate.crt
o    My_Domain_com.crt files
Note the root and intermediate files may have different names depends of the SSL Certificate, like DigiCert etc.
Note 2 all the below commands should be run as zimbra user starting ZCS 8.7 and above, and as a root user in ZCS 8.6 and below.
·         3. Cat the CA certs to form a single CA certificate chain file
 cat Root.crt Intermediate.crt > /tmp/commercial_ca.crt
·         4. Place the SSL certificate in /tmp/commercial.crt.
 cp my_domain_com.crt /tmp/commercial.crt
·         5. Copy private key file (which is generate at a time of CSR generation) on below path and rename it  commercial.key  .
/opt/Zimbra/ssl/Zimbra/commercial/commercial.key
·         6. Check that your SSL certificate, your private key and the Intermediate CA are OK, this step is important and you should not continue if you receive an error here:
/opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
·         7. Deploy the commercial certificate with zmcertmgr as the Zimbra user.
/opt/zimbra/bin/zmcertmgr deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt
** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key
Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match.
Valid Certificate: /tmp/commercial.crt: OK
** Copying /tmp/commercial.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Appending ca chain /tmp/commercial_ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt
** Importing certificate /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt to CACERTS as zcs-user-commercial_ca...done.
** NOTE: mailboxd must be restarted in order to use the imported certificate.
** Saving server config key zimbraSSLCertificate...done.
** Saving server config key zimbraSSLPrivateKey...done.
** Installing mta certificate and key...done.
** Installing slapd certificate and key...done.
** Installing proxy certificate and key...done.
** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done.
** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done.
** Installing CA to /opt/zimbra/conf/ca...done.
·         8. Restart the Zimbra Services
zmcontrol restart